Opening SecureFlowAgentjacking via Sentry MCP Telemetry Injection
Case summary & sources

AIDEFEND SecureFlow / SecureFlow Case Index

Tenet Threat Labs aidefend-sf0001

Agentjacking via Sentry MCP Telemetry Injection

  • Autonomous Agents
  • Tool Integrations & MCP
  • Resource Hijacking & Cost
  • Credential & Identity Theft

Tenet Threat Labs found 2,388 organizations with exposed Sentry DSNs and observed more than 100 coding agents execute a controlled validation package in authorized testing. The source-backed chain begins with a crafted Sentry error event, crosses the Sentry MCP telemetry boundary, steers an agent toward an npx command, probes only bounded exposure metadata on the developer or CI runtime, and sends responsible-disclosure identifiers to Tenet's advisory tracker. This flow does not represent Tenet's controlled package as malicious credential theft and does not claim that the tested organizations were breached.

Mapped threat techniques

Source